HACKER Q&A
📣 youeseh

Do we need captcha if we have 2FA?


I really dislike Captcha. It makes me feel like a robot. Now that Two Factor Authentication is becoming more normal, is Captcha beneficial?


  👤 ecesena Accepted Answer ✓
Captchas move a problem from one party to another. Service has a problem with bots, it adds a captcha, now the problem is on the legitimate users to prove they're not bots.

Like any technology, captcha has been invented at some point.

There's plenty of opportunity to solve the bot problem in a different way.

2FA doesn't address the same issue. It's not designed for the service to distinguish a human vs a bot. It's designed for users, to protect against account takeover.

P.S: I highly recommend this podcast on the history of recaptcha https://www.npr.org/2020/05/22/860884062/recaptcha-and-duoli...


👤 theandrewbailey
Captcha and 2FA address different concerns. A robot can still have a cell phone number, an email address, or TOTP generator.